Trac Spam

Colin Barrett colin at springsandstruts.com
Sat Nov 27 06:39:42 UTC 2010


There was a bot spamming our trac. I can only assume it's still trying but I've stopped it for now. I've removed TICKET_APPEND and TICKET_CREATE_SIMPLE from the "authenticated" group in the trac admin. This means regular users won't be able to comment on or create new tickets.

Rudy Richter reports that the earliest spam ticket was #14656 and the last was #14814.

John Bailey suggests installing TracSpamFilter filter, limiting the number of tickets per hour (for the authenticated group, presumably), requiring email addresses and "I also tuned the spam filter to negatively score users who did not have a name or an email address on their account -- which would likely not be a good idea for you guys since you probably have about a billion users out there".

Happy Thanksgiving from the spammers, I guess!

-Colin



More information about the devel mailing list